Privacy Policy
Privacy Policy | Thrive Holistic Health Hub
Effective Date: 12 August 2025
Thrive Holistic Health Hub (“we,” “us,” or “our”) is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy outlines how we collect, use, disclose, and protect your data in accordance with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the General Data Protection Regulation (GDPR), and other applicable laws.
1. What Personal Information We Collect
We may collect the following types of personal information:
-
Name, email address, phone number, and postal address
-
Date of birth and age
-
Sensitive information: health information you provide (symptoms, medical history, diagnoses, test results, medications, supplement use, allergies, genetic or biometric data, and other health-related details), as well as any information about racial or ethnic origin, religious beliefs, or sexual orientation voluntarily shared during the course of services
-
Payment and billing details (via third-party providers like Stripe)
-
Communications via email, social media, or messaging apps (e.g., WhatsApp)
-
Coaching session notes or recordings (where applicable)
-
Consent forms, health questionnaires, quizzes, surveys, and feedback forms
2. How We Collect Your Data
We use your personal information to:
-
Provide coaching, health, and wellness services
-
Personalise your assessments and protocols
-
Communicate with you regarding your program, booking, or feedback
-
Send newsletters, offers, and wellbeing resources (only if you opt in)
-
Comply with legal and professional obligations (e.g., record-keeping requirements)
-
Improve our services and internal processes
-
Perform aggregated, non-identifiable trend analysis for business and educational purposes
By providing personal information to us (whether via forms, email, booking systems, or verbally), you consent to its collection, storage, and use as outlined in this Privacy Policy.
4. Sharing and Disclosure
We will never sell or rent your personal information.
We may share your data in the following circumstances:
-
With subcontractors or partner practitioners (e.g., Amy Cotterill) involved in service delivery — such as somatic coaching or mindset support. These subcontractors are not provided access to client health history or blood work unless explicitly authorised by you in writing. All subcontractors operate under strict confidentiality agreements and data protection standards.
-
Subcontractors involved in non-clinical service delivery (e.g., somatic support) do not access your clinical records, blood work, or sensitive health data.
-
With third-party service providers (e.g., Stripe, Calendly, Jotform, ScoreApp, MailerLite, Meta/Facebook), all of which are GDPR- and/or Australian Privacy-compliant
-
Within a private client group (e.g., Facebook group used for education/community), only if you give prior written or recorded consent and where possible, all information is de-identified
-
When sharing general case studies, results, or insights within programs or platforms, all data is anonymised unless explicit consent is obtained
-
Where required by law (e.g., court orders, legal proceedings, health and safety obligations)
5. How We Store and Protect Your Information
We use secure, encrypted, and GDPR-compliant third-party platforms to store and process your data, including:
-
Jotform (typically hosted in the EU or US)
-
Google Workspace (data centres in Australia, Singapore, and the US)
-
ScoreApp (hosted in the UK/EU)
-
Calendly, Stripe, and Wix (regional data storage depending on service)
Your data is encrypted both at rest and in transit. Access is restricted to Charlene Manyweathers (Director) and authorised subcontractors under written confidentiality agreements.
We retain personal and health data for a minimum of 7 years for clinical and legal compliance (financial and transactional records may be retained longer if required under Australian tax law), after which it is securely deleted unless legally required otherwise.
On occasion, anonymised or de-identified case discussions may occur in closed professional groups for practitioner supervision and clinical review. These are shared with no identifying details and only for education or quality improvement purposes.
While we take all reasonable measures to protect your personal information, no system or method of transmission over the Internet can be guaranteed to be 100% secure.
6. Data Breach Protocol
In the unlikely event of a data breach involving your personal information that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches Scheme.
7. Your Rights
You may have rights under applicable privacy laws, including:
-
Accessing your personal data
-
Correcting inaccuracies in your records
-
Requesting deletion (subject to legal or regulatory requirements)
-
Withdrawing consent for communications
-
Opting out of marketing emails by clicking “unsubscribe” in any email or by contacting us directly
-
Lodging a complaint with a regulatory authority
To exercise these rights, contact: support@thriveholistichealthhub.com
8. International Data Transfers
Where personal data is transferred outside of Australia or the European Economic Area (EEA) (e.g., to subcontractors based in the UK), we ensure all data transfers comply with GDPR and relevant cross-border safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent legal mechanisms.
9. Cookies and Website Analytics
Our website and linked platforms may use cookies or similar tracking technologies (such as Facebook Pixel or Google Analytics) to enhance user experience and measure website traffic. You may choose to modify your browser settings to block or manage cookie preferences.
10. Third-Party Links
We may provide links to third-party websites (e.g., booking platforms, resources, or educational content). We are not responsible for the privacy practices or content of those sites. Please review their privacy policies before submitting any personal data.
11. Children’s Privacy
We do not knowingly collect or store data from individuals under the age of 16 without verified parental or guardian consent. If we become aware of such data being collected inadvertently, it will be securely deleted.
12. Changes to This Policy
Our website and linked platforms may use cookies or similar tracking technologies (such as Facebook Pixel or Google Analytics) to enhance user experience and measure website traffic. You may choose to modify your browser settings to block or manage cookie preferences.
13. Contact Us
If you have any questions or concerns about this policy or your data, please contact:
Charlie Manyweathers
Director, Thrive Holistic Health Hub
Email: support@thriveholistichealthhub.com
Australia (NSW)